Published: 22/12/2005 Updated: 08/03/2011
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in SPIP 1.8.2 and previous versions allows remote malicious users to inject arbitrary web script or HTML via unspecified parameters to (1) spip_login.php3 and (2) spip_pass.php3.

Vulnerable Product Search on Vulmon Subscribe to Product

spip spip 1.8.2

Vendor Advisories

Debian Bug report logs - #352078 XSS in SPIP spip_loginphp3 and spip_passphp3 Package: spip; Maintainer for spip is David Prévot <taffit@debianorg>; Source for spip is src:spip (PTS, buildd, popcon) Reported by: Micah Anderson <micah@debianorg> Date: Thu, 9 Feb 2006 16:18:44 UTC Severity: normal Done: Marti ...